๐Ÿ›ก๏ธ ื™ืกื•ื“ื•ืช ืžืขืจื›ื•ืช ื”ืคืขืœื” (OS) ืœืกื˜ื•ื“ื ื˜ื™ื ืœืกื™ื™ื‘ืจ โ€” ืžืืคืก ืœืคืจื•

๐Ÿ›ก๏ธ ื™ืกื•ื“ื•ืช ืžืขืจื›ื•ืช ื”ืคืขืœื” (OS) ืœืกื˜ื•ื“ื ื˜ื™ื ืœืกื™ื™ื‘ืจ โ€” ืžืืคืก ืœืคืจื•

ื”ื™ื›ื ืกื• ืœืžืจื›ื– ืžื•ืฉื’ื™ ืžืขืจื›ื•ืช ื”ื”ืคืขืœื” ื”ื—ื™ื•ื ื™ื™ื ืœืื‘ื˜ื—ืช ืกื™ื™ื‘ืจ. ื”ื‘ื™ื ื• ืืจื›ื™ื˜ืงื˜ื•ืจืช ืžืขืจื›ืช ื”ืคืขืœื”, ืชื”ืœื™ื›ื™ื, ื ื™ื”ื•ืœ ื–ื™ื›ืจื•ืŸ ื•ืขืงืจื•ื ื•ืช ืื‘ื˜ื—ื” ื‘ืกื™ืกื™ื™ื. ืœืžื“ื• ืžื™ื•ืžื ื•ื™ื•ืช ื ื™ื”ื•ืœ ืžืขืฉื™ื•ืช ืฉืœ ืœื™ื ื•ืงืก ื•-Windows, ื•ืงื‘ืœื• ืจืฉื™ืžืช ืžืฉื™ืžื•ืช ืžืขืฉื™ืช ืœื—ื™ื–ื•ืง ื”ืื‘ื˜ื—ื” ื‘ืฉื ื™ื”ื.

1) ืžื”ื™ ืžืขืจื›ืช ื”ืคืขืœื”?

ืžืขืจื›ืช ื”ืคืขืœื” (OS) ื”ื™ื ืฉื›ื‘ืช ื”ืชื•ื›ื ื” ืฉื‘ื™ืŸ ื”ืžืฉืชืžืฉื™ื/ื”ืืคืœื™ืงืฆื™ื•ืช ืœื‘ื™ืŸ ื”ื—ื•ืžืจื”. ื”ื™ื ืžืงืฆื” ื–ืžืŸ ืžืขื‘ื“, ืžื ื”ืœืช ื–ื™ื›ืจื•ืŸ ื•ืงื‘ืฆื™ื, ืฉื•ืœื˜ืช ื‘ื”ืชืงื ื™ื, ื•ืžืกืคืงืช ืžืžืฉืง ืขืงื‘ื™ ื“ืจืš ืงืจื™ืื•ืช ืžืขืจื›ืช ื•ึพShell/GUI ื›ื“ื™ ืฉืชื•ื›ื ื™ื•ืช ื™ืจื•ืฆื• ื‘ื™ืขื™ืœื•ืช ื•ื‘ื‘ื˜ื™ื—ื•ืช.


2) ืื—ืจื™ื•ืช ื”ืœื™ื‘ื” ืฉืœ ืžืขืจื›ืช ื”ืคืขืœื”

  • ื ื™ื”ื•ืœ ืชื”ืœื™ื›ื™ื ื•ึพCPU: ื™ืฆื™ืจื”/ืกื™ื•ื ืชื”ืœื™ื›ื™ื, ืชื–ืžื•ืŸ ืชืณืจื“ื™ื ืขืœ ืœื™ื‘ื•ืช.
  • ื ื™ื”ื•ืœ ื–ื™ื›ืจื•ืŸ: ื”ืงืฆืืช RAM, ื™ื™ืฉื•ื ื–ื™ื›ืจื•ืŸ ื•ื™ืจื˜ื•ืืœื™, ื•ืื›ื™ืคืช ื‘ื™ื“ื•ื“.
  • ื ื™ื”ื•ืœ ื”ืชืงื ื™ื ื•ืงืœื˜/ืคืœื˜: ื”ืคืฉื˜ืช ื“ื™ืกืงื™ื, ื›ืจื˜ื™ืกื™ ืจืฉืช, ืžืงืœื“ื•ืช ื‘ืืžืฆืขื•ืช ื“ืจื™ื™ื‘ืจื™ื.
  • ื ื™ื”ื•ืœ ืžืขืจื›ืช ืงื‘ืฆื™ื: ืืจื’ื•ืŸ ื ืชื•ื ื™ื ืœืงื‘ืฆื™ื/ืกืคืจื™ื•ืช ืขื ื”ืจืฉืื•ืช.
  • ืื‘ื˜ื—ื” ื•ื—ื™ืฉื•ื‘ ืฉื™ืžื•ืฉื™ื: ื–ื™ื”ื•ื™, ื”ืจืฉืื”, ืœื•ื’ื™ื, ืžื›ืกื•ืช.
  • ืžืžืฉืง ืœืžืฉืชืžืฉื™ื ื•ืœืชื•ื›ื ื•ืช: Shell/GUI ื•ึพAPI ืฉืœ ืงืจื™ืื•ืช ืžืขืจื›ืช ืœืืคืœื™ืงืฆื™ื•ืช.

3) ืืจื›ื™ื˜ืงื˜ื•ืจืช OS: Kernel, Shell ื•ืงืจื™ืื•ืช ืžืขืจื›ืช

  • Kernel (ืœื™ื‘ื”): ื”ืœื™ื‘ื” ื”ืžื•ืจืฉื™ืช ืฉืคื•ืขืœืช ื‘ึพKernel Mode, ืžื˜ืคืœืช ื‘ืชื–ืžื•ืŸ, ื–ื™ื›ืจื•ืŸ, ื“ืจื™ื™ื‘ืจื™ื, ืžืขืจื›ื•ืช ืงื‘ืฆื™ื ื•ึพIPC.
  • Shell: ื”ืžืžืฉืง ืœืžืฉืชืžืฉ (CLI ืื• GUI) ืฉืžืคืจืฉ ืคืงื•ื“ื•ืช ื•ืžืจื™ืฅ ืชื•ื›ื ื™ื•ืช.
  • ืงืจื™ืื•ืช ืžืขืจื›ืช (syscalls): ื ืงื•ื“ื•ืช ื›ื ื™ืกื” ืžื‘ื•ืงืจื•ืช ืžืฉื˜ื— ืžืฉืชืžืฉ ืœืฉื™ืจื•ืชื™ ื”ืœื™ื‘ื” (ืœืžืฉืœ open, read, execve, CreateProcessW).

ืกื’ื ื•ื ื•ืช ืœื™ื‘ื” ื ืคื•ืฆื™ื ื‘ืกื™ื™ื‘ืจ:

  • Monolithic (ืœืžืฉืœ Linux) โ€“ ืจื•ื‘ ื”ืฉื™ืจื•ืชื™ื ื‘ืœื™ื‘ื”.
  • Microkernel โ€“ ื“ื•ื—ืคื™ื ืฉื™ืจื•ืชื™ื ืœืฉื˜ื— ืžืฉืชืžืฉ ืœืžื•ื“ื•ืœืจื™ื•ืช.
  • Hybrid (ืœืžืฉืœ Windows, XNU) โ€“ ืฉื™ืœื•ื‘ ืฉืœ ื”ืฉื ื™ื™ื.

4) ืชื”ืœื™ื›ื™ื, ืชืณืจื“ื™ื ื•ืชื–ืžื•ืŸ CPU

  • ืชื”ืœื™ืš (Process): ืชื•ื›ื ื™ืช ืฉืจืฆื” ืขื ืžืจื—ื‘ ื›ืชื•ื‘ื•ืช ื•ื™ืจื˜ื•ืืœื™ ืžืฉืœื”.
  • ืชืณืจื“ (Thread): ื™ื—ื™ื“ืช ืชื–ืžื•ืŸ ื‘ืชื•ืš ืชื”ืœื™ืš, ื—ื•ืœืงืช ื–ื™ื›ืจื•ืŸ.
  • ืžืชื–ืžื ื™ื (Schedulers): ืžื—ืœื™ื˜ื™ื ืžื™ ืจืฅ ืขื›ืฉื™ื• (FCFS, SJF, Priority, Round-Robin, MLFBQ). ื”ื‘ื™ื ื• ืงื“ื™ืžื”/ืœื-ืงื“ื™ืžื”, ื”ื—ืœืคื•ืช ื”ืงืฉืจ (context switch) ื•ืจืขื‘ื•ืŸ ืœื˜ื•ื‘ืช ื‘ื™ืฆื•ืขื™ื ื•ื ื™ืชื•ื— ืคื•ืจื ื–ื™.

5) ื ื™ื”ื•ืœ ื–ื™ื›ืจื•ืŸ ื•ื–ื™ื›ืจื•ืŸ ื•ื™ืจื˜ื•ืืœื™

  • ื–ื™ื›ืจื•ืŸ ื•ื™ืจื˜ื•ืืœื™: ืžืขื ื™ืง ืœื›ืœ ืชื”ืœื™ืš ืžืจื—ื‘ ื›ืชื•ื‘ื•ืช ืœื•ื’ื™ ืžื‘ื•ื“ื“, ืžื’ื•ื‘ื” ื‘ึพRAM ื•ื‘ื“ื™ืกืง (ื“ืคื“ื•ืฃ/Paging).
  • ืืœื’ื•ืจื™ืชืžื™ ื”ื—ืœืคืช ื“ืคื™ื: (ืœืžืฉืœ FIFO, LRU, Optimal) ืžืื–ื ื™ื ืœื•ืงืœื™ื•ืช ืžื•ืœ ืชืงื•ืจื”.
  • ื”ื’ื ื”: (ืžืฆื‘ื™ User/Kernel, ื”ืจืฉืื•ืช ื“ืคื™ื) ืžื•ื ืขืช ืคื’ื™ืขื” ื”ื“ื“ื™ืช ื‘ื™ืŸ ืชื”ืœื™ื›ื™ื.

6) ืื—ืกื•ืŸ, ืžืขืจื›ื•ืช ืงื‘ืฆื™ื ื•ึพI/O

  • ืžืขืจื›ื•ืช ื”ืคืขืœื” ื—ื•ืฉืคื•ืช ืžืขืจื›ื•ืช ืงื‘ืฆื™ื (ืœืžืฉืœ ext4/XFS ื‘ืœื™ื ื•ืงืก, NTFS/ReFS ื‘ื•ื•ื™ื ื“ื•ื–) ืขื ืžื˜ืึพื“ื˜ื”, ื”ืจืฉืื•ืช/ACLs, ื•ึพJournaling ืœื—ื•ืกืŸ.
  • Block I/O (ื“ื™ืกืงื™ื/SSD) ืžืฉืชืžืฉ ื‘ืชื–ืžื•ื ื™ื; Character I/O (ืžืกื•ืคื™ื) ื”ื•ื ื–ืจืžื™.
  • ืชื–ืžื•ืŸ ื“ื™ืกืง (SCAN/LOOK) ื•ื‘ืืคืจื™ื ื’/ืงืืฉื™ื ื’ ืžืฉืคืจื™ื ืชืคื•ืงื”.

7) ืชื”ืœื™ืš ื”ืืชื—ื•ืœ ื•ืžืฆื‘ื™ ืคืขื•ืœื”

ืฉืœื‘ื™ื ื˜ื™ืคื•ืกื™ื™ื:

  1. ืงื•ืฉื—ืช UEFI/BIOS ืžื‘ืฆืขืช ืืชื—ื•ืœ ื—ื•ืžืจื” ื•ืžืืชืจืช Bootloader.
  2. Bootloader ื˜ื•ืขืŸ Kernel (ื•ึพinitramfs) ืœื–ื™ื›ืจื•ืŸ.
  3. ื”ืœื™ื‘ื” ืžืืชื—ืœืช ืชืชึพืžืขืจื›ื•ืช, ืžืขืžื™ืกื” Root FS ื•ืžืชื—ื™ืœื” ืชื”ืœื™ืš ืžืฉืชืžืฉ ืจืืฉื•ืŸ (init/systemd ืื• Windows Session Manager).
  4. ืฉื™ืจื•ืชื™ื ื•ืžื ื”ืœ ื”ืชื—ื‘ืจื•ืช/ืกืฉืŸ ืขื•ืœื™ื.

ืคืขื•ืœื•ืช ืžืฉืชืžืฉ ืงื•ืจื•ืช ื‘ึพUser Mode; ืœื™ื‘ืช ื”ืžืขืจื›ืช ื‘ึพKernel Mode.


8) ื™ืกื•ื“ื•ืช ืื‘ื˜ื—ื” (ื—ืฉื‘ื•ื ื•ืช, ACLs, ืžื“ื™ื ื™ื•ืช)

ืคืจื™ืžื™ื˜ื™ื‘ื™ื ืžืฉื•ืชืคื™ื:

  • ื–ื”ื•ื™ื•ืช ื•ืงื‘ื•ืฆื•ืช; ื”ืจืฉืื•ืช (rwx, ACLs), ื‘ืขืœื•ืช, ื•ื’ื‘ื•ืœื•ืช ื”ืจืฉืื”.
  • ืื›ื™ืคืช ืžื“ื™ื ื™ื•ืช (ืœืžืฉืœ UAC ื•ึพGroup Policy ื‘ึพWindows; DAC + MAC ื›ืžื• SELinux/AppArmor ื‘ืœื™ื ื•ืงืก).
  • ื‘ื™ืงื•ืจืช ื•ืœื•ื’ื™ื (Windows Event Logs, syslog/journald ื‘ืœื™ื ื•ืงืก).

ื”ื™ื’ื™ื™ื ืช ืื‘ื˜ื—ื”: ืขืงืจื•ืŸ ื”ืžื™ื ื™ืžื•ื, ืขื“ื›ื•ื ื™ื, ืื™ืžื•ืช ื—ื–ืง.


9) ื•ื™ืจื˜ื•ืืœื™ื–ืฆื™ื” ื•ืงื•ื ื˜ื™ื™ื ืจื™ื

  • ืžื›ื•ื ื•ืช ื•ื™ืจื˜ื•ืืœื™ื•ืช (VMs): ืžื“ืžื•ืช ื—ื•ืžืจื” ืžืœืื” ืœื”ืจื™ืฅ ืžืกืคืจ OS ืขืœ ืื•ืชื• ืฉืจืช.
  • ืงื•ื ื˜ื™ื™ื ืจื™ื: (namespaces/cgroups ื‘ืœื™ื ื•ืงืก) ืžื‘ื•ื“ื“ื™ื ืชื”ืœื™ื›ื™ื ืขืœ ื’ื‘ื™ ืื•ืชื” ืœื™ื‘ื”โ€”ืืชื—ื•ืœ ืžื”ื™ืจ ื•ืฆืคื™ืคื•ืช ื’ื‘ื•ื”ื”, ืžืขื•ืœื™ื ืœืคืจื•ื“ืงืฉืŸ ื•ืœืžืขื‘ื“ื•ืช.

10) ืกื•ื’ื™ OS: ื“ืกืงื˜ื•ืค, ืฉืจืชื™ื ื•ื ื™ื™ื“

  • ื“ืกืงื˜ื•ืค: Windows, macOS, ื”ืคืฆื•ืช Linuxโ€”ืคืจื•ื“ื•ืงื˜ื™ื‘ื™ื•ืช, ืคื™ืชื•ื—, ื’ื™ื™ืžื™ื ื’.
  • ืฉืจืช: Linux/Windows Serverโ€”ืฉื™ืจื•ืชื™ื ืœืœื GUI, ื›ื•ื•ื ื•ืŸ ื‘ื™ืฆื•ืขื™ื ื•ืื‘ื˜ื—ื”.
  • ื ื™ื™ื“: Android/iOSโ€”ืกื ื“ื‘ื•ืงืก ืœืืคืœื™ืงืฆื™ื•ืช ื•ืคืจื“ื™ื’ืžื•ืช ืื‘ื˜ื—ื” ื ื™ื™ื“ื•ืช.

11) Linux ืœืขื•ืžืช Windows: ืขืงืจื•ื ื•ืช ืื“ืžื™ื ื™ืกื˜ืจืฆื™ื” (Hands-On)

ื ื™ื”ื•ืœ ืžืฉืชืžืฉื™ื ื•ืงื‘ื•ืฆื•ืช

  • Linux: useradd, groupadd, passwd -l, ืงื‘ืฆื™ื /etc/passwd, /etc/shadow.
  • Windows: net user, net localgroup, ื•ึพMMC ืฉืœ Local Users & Groups.

ื—ื‘ื™ืœื•ืช ื•ืขื“ื›ื•ื ื™ื

  • Linux: ืžื ื”ืœื™ ื—ื‘ื™ืœื•ืช apt, dnf, yum, apk.
  • Windows: Winget/Chocolatey; ืฉื™ืจื•ืช Windows Update (wuauserv).

ืฉื™ืจื•ืชื™ื ื•ืืชื—ื•ืœ

  • Linux: systemctl enable|start <service> (systemd) ืื• service (SysV).
  • Windows: Service Control Manager (sc config/start/stop), ื•ึพServices.msc.

ืงื‘ืฆื™ื ื•ื”ืจืฉืื•ืช

  • Linux: chmod, chown, umask; ืžืขืจื›ื•ืช ืงื‘ืฆื™ื ext4/XFS.
  • Windows: ื”ืจืฉืื•ืช NTFS (GUI ืื• icacls), ื”ื•ืจืฉื” ื•ืื•ื“ื™ื˜ื™ื ื’.

ืœื•ื’ื™ื

  • Linux: /var/log/*, journalctl; logrotate ืœืกื‘ื‘ื™ ืœื•ื’ื™ื ื•ื“ื—ื™ืกื”.
  • Windows: Event Viewer โ†’ ืœื•ื’ื™ Application/Security/System; ืžื“ื™ื ื™ื•ืช ืฉืžื™ืจืช ืœื•ื’ื™ื ื‘ึพGroup Policy ืื• ื‘ืงื•ื ืกื•ืœ.

12) ืœื•ื’ื™ื, ื ื™ื˜ื•ืจ ื•ื˜ืจื‘ืœืฉื•ื˜ื™ื ื’

  • Linux: journalctl -u <svc>, dmesg, top/htop, ss -tulpn, lsof, strace.
  • Windows: ืžืกื ื ื™ื ื‘ึพEvent Viewer, Resource Monitor, Process Explorer, Get-WinEvent, Get-Process, netstat, ื›ืœื™ Sysinternals.
  • ื‘ืฆืขื• ืจื•ื˜ืฆื™ื™ืช ืœื•ื’ื™ื, ืจื›ื–ื• ืœื•ื’ื™ื (syslog โ†’ SIEM), ื•ืงื‘ืขื• ืžื“ื™ื ื™ื•ืช ืฉืžื™ืจื” ื•ื’ื™ืฉื”. logrotate ื”ื•ื ื”ื›ืœื™ ื”ืกื˜ื ื“ืจื˜ื™ ื‘ืœื™ื ื•ืงืก ืœืื•ื˜ื•ืžืฆื™ื™ืช ืจื•ื˜ืฆื™ื”.

13) ืฆืณืงึพืœื™ืกื˜ ื”ืงืฉื—ื” (Linux & Windows)

Linux

  • ื‘ื™ื˜ื•ืœ ื›ื ื™ืกืช root ื‘ึพSSH (PermitRootLogin no), ื”ืขื“ืคืช ืžืคืชื—ื•ืช.
  • ืขื“ื›ื•ืŸ ืฉื’ืจืชื™; ืžื™ื ื™ืžื•ื ื—ื‘ื™ืœื•ืช; ื—ื•ืžืชึพืืฉ (ufw/nftables).
  • ื”ืจืฉืื•ืช ืงื‘ืฆื™ื ืจื’ื™ืฉื™ื (ืœืžืฉืœ /etc/shadow ื”ืจืฉืื” 640, ื‘ืขืœื•ืช root:shadow).
  • ื”ื’ื“ืจืช logrotate ื•ืœื•ื’ื™ื ืžืจื›ื–ื™ื™ื; ื ื™ื˜ื•ืจ ื›ืฉืœื™ ื”ืชื—ื‘ืจื•ืช.

Windows

  • ืื›ื™ืคืช NLA ืœึพRDP; ื‘ื™ื˜ื•ืœ Guest; ืžื“ื™ื ื™ื•ืช ื ืขื™ืœื•ืช ื—ื–ืงื”.
  • ืฉื™ืจื•ืช Windows Update ืคืขื™ืœ; Defender + SmartScreen ืžื•ืคืขืœื™ื.
  • ืฆืžืฆื•ื ืฉื™ืžื•ืฉ ื‘ืžื ื”ืœื™ ืžืขืจื›ืช ืžืงื•ืžื™ื™ื; ืขืงืจื•ืŸ ื”ืžื™ื ื™ืžื•ื; AppLocker/WDAC.
  • ืงื‘ื™ืขืช ืฉืžื™ืจืช ืœื•ื’ื™ื ื•ื”ื–ืจืžื” ืœึพSIEM.

14) ืฉืืœื•ืช ื ืคื•ืฆื•ืช ืœืจืื™ื•ื ื•ืช/ืžื‘ื—ื ื™ื (ืขื ืชืฉื•ื‘ื•ืช)

  • ืžื”ื™ ืžืขืจื›ืช ื”ืคืขืœื”? ืฉื›ื‘ืช ืชื™ื•ื•ืš ื‘ื™ืŸ ื”ืžืฉืชืžืฉ/ืืคืœื™ืงืฆื™ื•ืช ืœื—ื•ืžืจื”; ืžื ื”ืœืช ืžืฉืื‘ื™ื ื•ืžืกืคืงืช ืฉื™ืจื•ืชื™ื.
  • Process ืœืขื•ืžืช Thread? ืœืชื”ืœื™ืš ืžืจื—ื‘ ื›ืชื•ื‘ื•ืช ืžืฉืœื•; ืชืณืจื“ื™ื ืžืฉืชืคื™ื ืืช ื”ื–ื™ื›ืจื•ืŸ ื•ื  ืงื•ื“ืช ื”ืชื–ืžื•ืŸ.
  • ืžื”ื• ื–ื™ื›ืจื•ืŸ ื•ื™ืจื˜ื•ืืœื™? ื”ืคืฉื˜ื” ืฉื ื•ืชื ืช ืœืชื”ืœื™ื›ื™ื ืžืจื—ื‘ื™ ื›ืชื•ื‘ื•ืช ืžื‘ื•ื“ื“ื™ื ื‘ืขื–ืจืช ื“ืคื“ื•ืฃ ืœื“ื™ืกืง.
  • Kernel ืœืขื•ืžืช Shell? Kernel = ืœื™ื‘ื” ืคืจื™ื‘ื™ืœื’ื™ืช; Shell = ืžืžืฉืง ืžืฉืชืžืฉ (CLI/GUI) ื”ืžื“ื‘ืจ ืขื ื”ืœื™ื‘ื” ื‘ืงืจื™ืื•ืช ืžืขืจื›ืช.
  • Monolithic ืœืขื•ืžืช Microkernel? ืžื•ื ื•ืœื™ื˜ื™โ€”ืจื•ื‘ ื”ืฉื™ืจื•ืชื™ื ื‘ืœื™ื‘ื”; ืžื™ืงืจื•โ€”ืœื™ื‘ื” ืžืฆื•ืžืฆืžืช, ืฉื™ืจื•ืชื™ื ื‘ืฉื˜ื— ืžืฉืชืžืฉ.

15) ืžื™ื ื™ึพืžืขื‘ื“ื•ืช: ื ืกื• ืขื›ืฉื™ื•

ื”ืจื™ืฆื• ื‘ืกื‘ื™ื‘ืช VM/ืงื•ื ื˜ื™ื™ื ืจ ื—ื“ึพืคืขืžื™ืช.

Linux

# 1) ืžืฉืชืžืฉื™ื ื•ืงื‘ื•ืฆื•ืช
sudo groupadd secops && sudo useradd -m -g secops -s /usr/sbin/nologin secops && sudo passwd -l secops

# 2) ื—ื‘ื™ืœื•ืช (Debian/Ubuntu)
sudo apt-get update -y && sudo apt-get install -y htop && htop --version && sudo apt-get remove -y htop

# 3) ืฉื™ืจื•ืชื™ื (systemd)
sudo systemctl enable --now cron || echo "Not available here"

# 4) ืจื•ื˜ืฆื™ื™ืช ืœื•ื’ื™ื
cat | sudo tee /etc/logrotate.d/custom <<'EOF'
/var/log/custom.log {
  weekly
  rotate 4
  compress
  missingok
  notifempty
  create 0640 root adm
}
EOF
sudo touch /var/log/custom.log && sudo chown root:adm /var/log/custom.log && sudo chmod 0640 /var/log/custom.log

# 5) ื”ืงืฉื—ืช SSH
sudo sed -i 's/^#\?PermitRootLogin.*/PermitRootLogin no/' /etc/ssh/sshd_config && sudo systemctl restart ssh || true

Windows (PowerShell ื›ืžื ื”ืœ)

# 1) ืžืฉืชืžืฉื™ื ื•ืงื‘ื•ืฆื•ืช
net user secops /add /y
net localgroup "Users" secops /add

# 2) ื—ื‘ื™ืœื•ืช ื‘ืขื–ืจืช winget (ืื• Chocolatey ืื ืงื™ื™ื)
winget install --id=7zip.7zip -e; winget uninstall --id=7zip.7zip -e

# 3) ืฉื™ืจื•ืชื™ื
sc config wuauserv start= auto
sc start wuauserv

# 4) ืฉืžื™ืจืช ืœื•ื’ื™ื (ื“ื•ื’ืžื”: Application ืœ-64MB)
wevtutil sl Application /ms:67108864

# 5) RDP + NLA ืžื•ืžืœืฅ (Group Policy / System Properties > Remote)

16) ืžื™ืœื•ืŸ ืžื•ื ื—ื™ื

  • ACL: ืจืฉื™ืžื•ืช ื‘ืงืจืช ื’ื™ืฉื” โ€“ ื”ืจืฉืื•ืช ื’ืจื ื•ืœืจื™ื•ืช ืขืœ ืื•ื‘ื™ื™ืงื˜ื™ื.
  • Context Switch: ืฉืžื™ืจืช/ืฉื—ื–ื•ืจ ืžืฆื‘ CPU ืœืžืขื‘ืจ ื‘ื™ืŸ ืชืณืจื“ื™ื.
  • Journaling FS: ืžืขืจื›ืช ืงื‘ืฆื™ื ืฉืจื•ืฉืžืช ืฉื™ื ื•ื™ื™ื ืœื™ื•ืžืŸ ืœืฉืจื™ื“ื•ืช ื‘ืงืจื™ืกื”.
  • Kernel/User Mode: ืจืžื•ืช ื”ืจืฉืื” ืฉืœ ื”ึพCPU ื”ืงื•ื‘ืขื•ืช ืคืขื•ืœื•ืช ืžื•ืชืจื•ืช.
  • Paging (ื“ืคื“ื•ืฃ): ื”ืขื‘ืจืช ื“ืคื™ื ื‘ื™ืŸ RAM ืœื“ื™ืกืง.
  • Preemption (ืงื“ื™ืžื”): ื”ืžืชื–ืžืŸ ืขื•ืฆืจ ืชืณืจื“ ืจืฅ ื›ื“ื™ ืœื”ืจื™ืฅ ืื—ืจ.
  • System Call (ืงืจื™ืืช ืžืขืจื›ืช): ื’ื‘ื•ืœ ื”ึพAPI ืžืฉื˜ื— ืžืฉืชืžืฉ ืœืฉื™ืจื•ืชื™ ื”ืœื™ื‘ื”.

17) ื˜ื™ืคื™ื ืœึพSEO ืœืคืจืกื•ื ื‘ื‘ืœื•ื’ Cyber8200

  • ืฉืœื‘ื• ืžื™ืœื•ืช ืžืคืชื— ื‘ื›ื•ืชืจื•ืช H1/H2: โ€œOperating System Basicsโ€, โ€œOS for Cybersecurityโ€, โ€œLinux vs Windows administrationโ€.
  • ื”ื•ืกื™ืคื• ืงื™ืฉื•ืจื™ื ืคื ื™ืžื™ื™ื ืœืคื•ืกื˜ื™ื ืขืœ Linux CLI, Windows Registry, SIEM/Logging, ื•ึพThreat Hunting.
  • ืกืคืงื• Cheat Sheet ืœื”ื•ืจื“ื” ื•ึพืกืงืจื™ืคื˜ื™ ืžืขื‘ื“ื” ืœื”ื’ื“ืœืช ื–ืžืŸ ื”ืฉื”ื™ื™ื” ื•ืงื™ืฉื•ืจื™ื ื ื›ื ืกื™ื.
  • ื”ื•ืกื™ืคื• ืžืจืงืจ JSON-LD (FAQPage) ืœืฉืืœื•ืช ื•ืชืฉื•ื‘ื•ืช ื›ื“ื™ ืœืฉืคืจ ืชื•ืฆืื•ืช ืขืฉื™ืจื•ืช.
๐Ÿš€ ืžื•ื›ื ื™ื ืœืขืœื•ืช ืจืžื”?

ืงื— ืืช ืงืจื™ื™ืจืช ื”ืกื™ื™ื‘ืจ ืฉืœืš ืœืฉืœื‘ ื”ื‘ื

ืื ืžืฆืืชื ืืช ื”ืชื•ื›ืŸ ื”ื–ื” ื‘ืขืœ ืขืจืš, ืชืืจื• ืœืขืฆืžื›ื ืžื” ืชื•ื›ืœื• ืœื”ืฉื™ื’ ืขื ืชื•ื›ื ื™ืช ื”ื”ื›ืฉืจื” ื”ืžืงื™ืคื” ื•ื”ืืœื™ื˜ื™ืกื˜ื™ืช ืฉืœื ื• ื‘ืช 47 ืฉื‘ื•ืขื•ืช. ื”ืฆื˜ืจืคื• ืœื™ื•ืชืจ ืž-1,200 ืกื˜ื•ื“ื ื˜ื™ื ืฉืฉื™ื ื• ืืช ื”ืงืจื™ื™ืจื” ืฉืœื”ื ื‘ืขื–ืจืช ื˜ื›ื ื™ืงื•ืช ื™ื—ื™ื“ื” 8200.

97% ืฉื™ืขื•ืจ ื”ืฉืžื” ืœืขื‘ื•ื“ื”
ื˜ื›ื ื™ืงื•ืช ื™ื—ื™ื“ื” 8200 ืขื™ืœื™ืช
42 ืžืขื‘ื“ื•ืช ืžืขืฉื™ื•ืช